D den a díky za zájem :
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-12-2014 01
Ran by Jirka (administrator) on JIRKA-PC on 22-12-2014 09:52:41
Running from C:\Users\Jirka\Desktop
Loaded Profiles: Jirka & UpdatusUser (Available profiles: Jirka & UpdatusUser)
Platform: Microsoft® Windows Vista™ Business Service Pack 2 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 9
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(PixArt Imaging Incorporation) C:\Windows\Pixart\Pac7302\Monitor.exe
(FileOpen Systems Inc.) C:\Program Files\FileOpen\Services\FileOpenBroker32.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(American Power Conversion Corporation) C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
(Gemius) C:\Program Files\NetSoftware\NetSoftware.exe
(Software602 a.s.) C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
(American Power Conversion Corporation) C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
(FileOpen Systems Inc.) C:\Program Files\FileOpen\Services\FileOpenManagerService32.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Windows\System32\sdclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\ielowutil.exe
(forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-18] (Microsoft Corporation)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [151552 2006-05-11] (Intel Corporation)
HKLM\...\Run: [PAC7302_Monitor] => C:\Windows\PixArt\PAC7302\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [689488 2008-03-10] (CANON INC.)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1848648 2008-03-17] (CANON INC.)
HKLM\...\Run: [FileOpenBroker] => C:\Program Files\FileOpen\Services\FileOpenBroker32.exe [840624 2012-11-07] (FileOpen Systems Inc.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3653136 2014-11-09] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Run: [NetSoftware] => C:\Program Files\NetSoftware\Starter.exe [218112 2014-12-03] (Gemius)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-473776709-23561653-1376516071-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-18] (Microsoft Corporation)
HKU\S-1-5-21-473776709-23561653-1376516071-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Jirka\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-473776709-23561653-1376516071-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Jirka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-473776709-23561653-1376516071-1000\...\RunOnce: [Adobe Speed Launcher] => 1419190514
HKU\S-1-5-21-473776709-23561653-1376516071-1000\...\MountPoints2: {368defa3-8bb0-11e2-9ac7-0019d171c286} - H:\Autorun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2066.1.9B05 PID_0083
HKU\S-1-5-21-473776709-23561653-1376516071-1000\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess?
HKU\S-1-5-21-473776709-23561653-1376516071-1001\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-473776709-23561653-1376516071-1001\...\Run: [T-Mobile CManager] => C:\Program Files\T-Mobile\T-Mobile Internet Manager\Manager.exe [2166552 2013-10-31] (Gemfor s.r.o.)
HKU\S-1-5-21-473776709-23561653-1376516071-1001\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess?
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk
ShortcutTarget: APC UPS Status.lnk -> C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com
HKU\S-1-5-21-473776709-23561653-1376516071-1000\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.idnes.cz/
HKU\S-1-5-21-473776709-23561653-1376516071-1000\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ie
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-473776709-23561653-1376516071-1000 -> DefaultScope {8BA9C4A8-FC66-4918-A79E-AB4B5470BAC9} URL =
http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKU\S-1-5-21-473776709-23561653-1376516071-1000 -> 5B8D147C1877690E087CE3668C8CD123 URL =
http://www.firmy.cz/phr/{searchTerms}
SearchScopes: HKU\S-1-5-21-473776709-23561653-1376516071-1000 -> 60AD7DF367A51D78AE25011EFFE3FF4D URL =
http://www.zbozi.cz/?sourceid=quicksear ... earchTerms}
SearchScopes: HKU\S-1-5-21-473776709-23561653-1376516071-1000 -> DA175516DCC6659CF9D0C9796A42161D URL =
http://www.mapy.cz/?sourceid=quicksearc ... earchTerms}
SearchScopes: HKU\S-1-5-21-473776709-23561653-1376516071-1000 -> F35A53397BA0816FC7057CF7B8A37903 URL =
http://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-473776709-23561653-1376516071-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
http://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-473776709-23561653-1376516071-1000 -> {8BA9C4A8-FC66-4918-A79E-AB4B5470BAC9} URL =
http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKU\S-1-5-21-473776709-23561653-1376516071-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL =
https://mysearch.avg.com/search?cid={E7 ... 2014-12-10 07:55:23&v=4.0.5.7&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-473776709-23561653-1376516071-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Internet Panel -> {CE7C3CF0-4B15-11D1-ABED-709549C10000} -> C:\Program Files\NetSoftware\IEHelper.dll (Gemius)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {F680B28A-3AEE-4C88-93ED-45AE9215C128}
https://adisepo.mfcr.cz/adistc/adis/idp ... tsignx.cab
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Společnost Microsoft)
Hosts: 127.0.0.1 localhost
Tcpip\Parameters: [DhcpNameServer] 79.98.72.27 79.98.72.2
FireFox:
========
FF ProfilePath: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\1osd4hsz.default
FF Homepage: hxxp://
www.idnes.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @software602.cz/602XML Filler -> C:\Program Files\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\1osd4hsz.default\searchplugins\firmy.cz-165656.xml
FF SearchPlugin: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\1osd4hsz.default\searchplugins\seznam.cz-165656.xml
FF SearchPlugin: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\1osd4hsz.default\searchplugins\videa.seznam.cz-165656.xml
FF SearchPlugin: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\1osd4hsz.default\searchplugins\zbozi.cz-165656.xml
FF Extension: DownloadHelper - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\1osd4hsz.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-12-11]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-02-15]
FF HKU\S-1-5-21-473776709-23561653-1376516071-1000\...\Firefox\Extensions: [
gemgecko@gemius.com] - C:\Program Files\NetSoftware\gemgecko_ext
FF Extension: Výzkum NetMonitor - C:\Program Files\NetSoftware\gemgecko_ext [2014-11-28]
FF Extension: No Name -
gemgecko@gemius.com [Not Found]
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR HomePage: Default -> hxxp://istart.webssearches.com/?type=hp&ts=1419152751&from=cvs&uid=WDCXWD2502ABYS-18B7A0_WD-WCAT1704584445844
CHR StartupUrls: Default -> "hxxp://istart.webssearches.com/?type=hp&ts=1419152751&from=cvs&uid=WDCXWD2502ABYS-18B7A0_WD-WCAT1704584445844"
CHR DefaultSearchKeyword: Default -> webssearches
CHR DefaultSuggestURL: Default ->
CHR Profile: C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Яндекс) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aminlpmkfcdibgpgfajlgnamicjckkjf [2014-11-02]
CHR Extension: (Netpanel study) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kegdldmohomdaelnepdpbkdhfemobdgl [2014-11-30]
CHR Extension: (Peněženka Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-02]
CHR HKLM\...\Chrome\Extension: [aminlpmkfcdibgpgfajlgnamicjckkjf] - No Path
CHR HKU\S-1-5-21-473776709-23561653-1376516071-1000\...\Chrome\Extension: [kegdldmohomdaelnepdpbkdhfemobdgl] - No Path
CHR StartMenuInternet: Google Chrome - Chrome.exe
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 602XML Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 APC UPS Service; C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe [689408 2007-07-19] (American Power Conversion Corporation)
S2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3488784 2014-11-09] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [298080 2014-11-09] (AVG Technologies CZ, s.r.o.)
R2 FileOpenManagerService; C:\Program Files\FileOpen\Services\FileOpenManagerService32.exe [213432 2012-11-07] (FileOpen Systems Inc.)
R2 IAANTMON; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [90112 2006-05-11] (Intel Corporation) [File not signed]
R2 MbnExt; C:\Program Files\T-Mobile\T-Mobile Internet Manager\MbnExt.dll [417128 2013-12-02] (Gemfor s.r.o.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32408 2011-08-15] (Google Inc)
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [213784 2014-10-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147736 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [192792 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [230680 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [200984 2014-10-10] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [43296 2014-12-10] (AVG Technologies)
S3 cpuz136; C:\Program Files\CPUID\PC Wizard 2013\pcwiz_x32.sys [25320 2013-08-24] (CPUID)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-10] (Společnost Microsoft)
S3 massfilter; C:\Windows\System32\drivers\massfilter.sys [9216 2011-04-13] (MBB Incorporated)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R3 PAC7302; C:\Windows\System32\DRIVERS\PAC7302.SYS [457856 2007-06-14] (PixArt Imaging Inc.)
S3 sfng32; C:\Windows\System32\drivers\sfng32.sys [41728 2005-12-02] (Sonic Focus, Inc) [File not signed]
S3 zghsmdm; C:\Windows\System32\DRIVERS\zghsmdm.sys [113688 2011-08-15] (ZTE Incorporated)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 cpuz135; \??\C:\Program Files\CPUID\PC Wizard 2012\pcwiz_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 STHDA; system32\drivers\sthda.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-22 09:52 - 2014-12-22 09:53 - 00017715 _____ () C:\Users\Jirka\Desktop\FRST.txt
2014-12-22 09:52 - 2014-12-22 09:52 - 00000000 ____D () C:\FRST
2014-12-22 09:46 - 2014-12-22 09:46 - 01113600 _____ (Farbar) C:\Users\Jirka\Desktop\FRST.exe
2014-12-22 09:46 - 2014-12-22 09:46 - 00112640 _____ (forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
2014-12-21 18:09 - 2014-12-21 18:10 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Jirka\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-21 13:44 - 2014-12-21 17:53 - 00049072 _____ () C:\Windows\PFRO.log
2014-12-21 13:10 - 2014-12-21 13:10 - 02166272 _____ () C:\Users\Jirka\Downloads\adwcleaner_4.105.exe
2014-12-21 11:14 - 2014-12-21 11:14 - 15670360 _____ () C:\Users\Jirka\Downloads\RogueKiller.exe
2014-12-21 11:12 - 2014-12-21 11:12 - 01054912 _____ (Adobe) C:\Users\Jirka\Downloads\install_flashplayer16x32au_gtba_chra_dy_aaa_aih.exe
2014-12-16 20:42 - 2014-12-16 20:49 - 00000000 ____D () C:\ProgramData\WinZip
2014-12-16 16:05 - 2014-12-16 16:06 - 00000000 ____D () C:\Program Files\CrystalDiskInfo
2014-12-16 16:05 - 2014-12-16 16:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2014-12-15 10:08 - 2014-12-15 10:08 - 00007284 _____ () C:\Users\Jirka\novewawa.txt
2014-12-12 17:39 - 2014-12-12 17:39 - 00000000 ____D () C:\Program Files\ESET
2014-12-11 14:47 - 2014-12-11 14:47 - 00000864 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-12-11 13:05 - 2014-11-07 02:33 - 00974848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-11 13:05 - 2014-11-04 01:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-11 13:00 - 2014-12-03 03:06 - 00278528 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-12-10 16:35 - 2014-11-24 21:44 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-12-10 16:35 - 2014-11-24 21:41 - 12369920 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-10 16:35 - 2014-11-24 21:40 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-10 16:35 - 2014-11-24 21:37 - 09740800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-10 16:35 - 2014-11-24 21:35 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-10 16:35 - 2014-11-24 21:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-10 16:35 - 2014-11-24 21:34 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-10 16:35 - 2014-11-24 21:34 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-12-10 16:35 - 2014-11-24 21:33 - 01802752 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-10 16:35 - 2014-11-24 21:33 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-12-10 16:35 - 2014-11-24 21:33 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-10 16:35 - 2014-11-24 21:33 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-10 16:35 - 2014-11-24 21:33 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-10 16:35 - 2014-11-24 21:33 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-10 16:35 - 2014-11-24 21:33 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-12-10 16:35 - 2014-11-24 21:32 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-10 16:35 - 2014-11-24 21:32 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-10 16:35 - 2014-11-24 21:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-10 16:35 - 2014-11-24 21:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-10 16:35 - 2014-11-24 21:32 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-10 16:35 - 2014-11-24 21:32 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-12-10 16:35 - 2014-11-24 21:32 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-12-10 07:55 - 2014-12-10 16:17 - 00000000 ____D () C:\Users\Jirka\AppData\Local\AVG Web TuneUp
2014-12-10 07:55 - 2014-12-10 07:55 - 00043296 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys
2014-12-10 07:55 - 2014-12-10 07:55 - 00000000 ____D () C:\ProgramData\AVG Web TuneUp
2014-12-10 07:55 - 2014-12-10 07:55 - 00000000 ____D () C:\Program Files\AVG Web TuneUp
2014-12-02 21:56 - 2014-12-02 21:56 - 14762832 _____ (Stardust Software) C:\Users\Jirka\Downloads\money-s3-15002-upd-15001-cz.exe
2014-12-01 17:21 - 2014-12-01 17:21 - 00000000 ____D () C:\Users\Jirka\Documents\eagle
2014-12-01 17:17 - 2014-12-01 17:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EAGLE Layout Editor 7.2.0
2014-12-01 17:16 - 2014-12-01 17:17 - 00000000 ____D () C:\EAGLE-7.2.0
2014-12-01 17:16 - 2014-12-01 17:16 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\CadSoft
2014-12-01 08:59 - 2014-12-01 09:18 - 00000243 _____ () C:\Users\Jirka\Documents\TEtmp.rcl
2014-11-28 08:16 - 2014-12-21 21:27 - 00000000 ____D () C:\ProgramData\NetSoftware
2014-11-28 08:16 - 2014-11-28 08:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetSoftware
2014-11-28 08:15 - 2014-12-22 09:52 - 00000000 ____D () C:\Program Files\NetSoftware
2014-11-28 08:15 - 2014-11-28 08:15 - 02401096 _____ () C:\Users\Jirka\Downloads\nsinstall.exe
2014-11-27 17:04 - 2014-12-21 13:43 - 00000863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-27 17:04 - 2014-12-11 12:32 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-11-27 17:03 - 2014-11-27 17:04 - 36286104 _____ () C:\Users\Jirka\Downloads\FirefoxSetup33.1.1cz.exe
2014-11-26 20:53 - 2014-11-26 20:53 - 05162080 _____ (Piriform Ltd) C:\Users\Jirka\Downloads\ccsetup500.exe
2014-11-22 14:05 - 2014-11-22 14:05 - 00002106 _____ () C:\Users\Jirka\Documents\Revize spotřebiče.zpr
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-22 09:43 - 2006-11-02 13:52 - 01272601 _____ () C:\Windows\WindowsUpdate.log
2014-12-22 09:42 - 2014-11-02 13:40 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-22 09:39 - 2014-11-02 13:40 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-22 09:37 - 2013-02-16 00:11 - 00000000 ____D () C:\ProgramData\MFAData
2014-12-22 09:34 - 2013-02-17 14:22 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-21 21:02 - 2006-11-02 11:33 - 01532750 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-21 20:40 - 2013-12-27 18:27 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Seznam.cz
2014-12-21 20:35 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-21 20:35 - 2006-11-02 13:47 - 00004576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-21 20:35 - 2006-11-02 13:47 - 00004576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-21 20:33 - 2006-11-02 14:01 - 00032528 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-21 13:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\nap
2014-12-21 13:43 - 2014-11-02 13:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-21 13:43 - 2014-09-13 08:12 - 00000000 ____D () C:\AdwCleaner
2014-12-21 13:43 - 2013-02-15 19:55 - 00000966 _____ () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-21 11:34 - 2013-02-28 08:03 - 00000000 ____D () C:\Users\Jirka\AppData\Local\CrashDumps
2014-12-21 11:15 - 2014-07-03 13:15 - 00034808 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-12-21 11:09 - 2014-08-18 16:28 - 00000000 ____D () C:\Program Files\7-Zip
2014-12-21 11:07 - 2014-03-16 20:06 - 00000000 ____D () C:\Program Files\Seznam.cz
2014-12-20 14:23 - 2013-02-16 13:21 - 00000000 ____D () C:\Users\Jirka\Desktop\chovy
2014-12-19 22:07 - 2013-10-26 13:22 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\vlc
2014-12-19 21:08 - 2014-11-17 14:06 - 00000000 ____D () C:\Users\Jirka\dwhelper
2014-12-16 20:42 - 2013-02-15 19:54 - 00000000 ____D () C:\Users\Jirka
2014-12-15 20:39 - 2013-04-12 18:41 - 00001914 _____ () C:\Users\Public\Desktop\Money S3.lnk
2014-12-15 10:01 - 2013-02-16 13:10 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-12-14 17:16 - 2013-02-16 13:22 - 00000000 ____D () C:\Users\Jirka\Documents\Word z W98
2014-12-13 19:18 - 2013-02-16 13:29 - 184832811 _____ () C:\Users\Jirka\Documents\zaloha.ar!
2014-12-13 09:04 - 2013-02-26 12:26 - 00000000 ____D () C:\Users\Jirka\Documents\Hes
2014-12-11 13:39 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\rescache
2014-12-11 13:05 - 2013-08-15 12:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-11 13:01 - 2006-11-02 11:24 - 109818608 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-12-10 08:34 - 2013-02-17 14:22 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-12-10 08:34 - 2013-02-17 14:22 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-12-10 07:55 - 2014-11-11 08:54 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-12-07 12:01 - 2014-10-27 17:09 - 00013621 _____ () C:\Users\Jirka\Documents\AOPK rev.odt
2014-12-01 16:02 - 2014-10-09 16:08 - 00082372 _____ () C:\Users\Jirka\Documents\Revize známky16.odt
2014-11-30 09:29 - 2013-03-02 08:38 - 00000000 ____D () C:\Program Files\Recuva
2014-11-28 16:12 - 2013-10-22 16:36 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\dvdcss
2014-11-26 20:54 - 2013-02-17 17:22 - 00000000 ____D () C:\Program Files\CCleaner
Files to move or delete:
====================
C:\Users\Jirka\en_res.dll
C:\Users\Jirka\es_res.dll
C:\Users\Jirka\fr_res.dll
C:\Users\Jirka\grm_res.dll
C:\Users\Jirka\it_res.dll
C:\Users\Jirka\jp_res.dll
C:\Users\Jirka\mfc80u.dll
C:\Users\Jirka\msvcr80.dll
C:\Users\Jirka\PCPE Setup.exe
C:\Users\Jirka\pt_res.dll
C:\Users\Jirka\ResourceReader.dll
C:\Users\Jirka\ru_res.dll
C:\Users\Jirka\zh_res.dll
C:\Users\Jirka\AppData\Roaming\cache.ini
Some content of TEMP:
====================
C:\Users\Jirka\AppData\Local\Temp\Quarantine.exe
C:\Users\Jirka\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: AVG AntiVirus Free Edition 2015 (Disabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: AVG AntiVirus Free Edition 2015 (Disabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Jirka\Desktop" je 8044 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================